1. Proposed title of this feature request
Deploy the ImageRegistry with a storage Bucket without public endpoints
2. What is the nature and description of the request?
Storage Bucket without public endpoints and have the ImageRegistry operator create a private endpoint
(requires a separate domain name to be supplied)
3. Why does the customer need this? (List the business requirements here)
Not using a private endpoint leads to from my customer to have a security exception in filtering rules. This security exception could impact PCIDSS certification. Loosing this certification is not possible it is important to be able to be fully private in this context.
In addition it is also raising security alert breaking Azure security recommandation. It is confusing for my customer since Openshift doesn't seem to follow Azure security recommandations (cf screenshot from Azure console)
4. List any affected packages or components
Check storage accounts created for imageregistry
- relates to
-
IR-302 Phase 1&2: Support Azure storage accounts with public network access disabled
- Closed
- links to